Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-0199

Опубликовано: 20 янв. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-0199: libreswan security update (IMPORTANT)

[4.4-4.0.1]

  • Add libreswan-oracle.patch to detect Oracle Linux distro

[4.4-4]

  • Resolves: rhbz#2036902 rebuild to enable rpminspect

[4.4-3]

  • Resolves: rhbz#2036902: fix patch application

[4.4-2]

  • Resolves: rhbz#2036902 ikev1: disable diagnostics logging on receiving malformed packets

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libreswan

4.4-4.0.1.el8_5

Oracle Linux x86_64

libreswan

4.4-4.0.1.el8_5

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

CVSS3: 7.5
redhat
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

CVSS3: 7.5
nvd
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

CVSS3: 7.5
debian
около 4 лет назад

Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of ...

rocky
около 4 лет назад

Important: libreswan security update